Impact
The vulnerability is a heap-based buffer overflow in the Windows Biometric Service that allows an attacker who already has authorized access to a target machine to execute code with elevated privileges. By sending crafted data over the network, the attacker can trigger the overflow and gain SYSTEM level access, compromising confidentiality, integrity, and availability of the affected system.
Affected Systems
This flaw affects Microsoft Windows 10 releases 1607, 1809, 21H2, and 22H2, Windows 11 releases 23H2, 24H2, 25H2, and 26H1 (both ARM64 and x64 where applicable), and Windows Server editions 2016, 2019, 2022, and 2025. The vulnerability is present in both standard and server core installations across the listed operating system versions.
Risk and Exploitability
The CVSS base score of 8 evaluates this as a high‑severity issue. No EPSS score is available, but because the vulnerability requires that the attacker have network interaction with a machine where the Windows Biometric Service is running, the exploitation probability is largely dependent on the presence of that service and on the attacker’s ability to reach the target. While the vulnerability is not listed in CISA’s KEV catalog, the potential to elevate privileges and gain SYSTEM access means it should be treated as a serious risk when the affected OS versions are in use.
OpenCVE Enrichment